Password strengths leaked: what it means and what to do

Risk level: medium. Can you change it: yes. Found in 1 breaches in this directory.

What this data is

A score or label, such as weak, fair or strong, that a website calculated when you set your password and then stored alongside your account.

The risk on its own

The score is not the password and cannot be used to log in. What it does is sort victims: a weak rating tells an attacker that a short list of common passwords will probably work. It also reveals roughly how long or complex the password is, which narrows guessing.

The risk combined with other data

With your email address it becomes a targeting list for password spraying, where attackers try common passwords against the accounts most likely to fall. If the same weak password is reused elsewhere, every other account with that email address is exposed too. A strong rating offers less protection than it seems if the password was reused.

How criminals use it

  • Attackers filter the leak for accounts rated weak and try the most common passwords against each email address.
  • Accounts rated weak are tried on email, banking and shopping sites, on the assumption that weak passwords are reused.
  • A rating that reveals a short password lets an attacker cut the guessing job down to a manageable size.

What to do now

  1. Change the password on the breached account to a long unique one, whatever rating it had.
  2. Use a password generator and a password manager so every account gets a different password.
  3. Test any password you still rely on in a password checker, and replace every one it flags as weak or previously leaked.
  4. Switch on two-factor authentication for email, banking and social accounts so a guessed password is not enough.

Frequently asked questions

Can someone see my password from its strength score?

No. The score only describes how strong the password looked. It helps attackers choose targets but does not reveal the password.

My password was rated strong. Do I need to change it?

Change it if you used it anywhere else. Strength does not help when the same password leaks from a second site.

Why would a site save the score?

Usually for analytics or to nag users with weak passwords. It should not have been stored beside account details.

Breaches that exposed this data

  • Scentbird: 2020-06-22, 5.8M accounts, Dates of birth, Email addresses, Genders, Names, Password strengths, Passwords

Tools that help

Related guides

Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.